Skip to main content

Module lifecycle

Module lifecycle 

Source
Expand description

Typed participant lifecycle state and transitions.

The deviations here are mandated by docs/design/LP-EXTRACTION-GOAL.md: detach cells retain a terminalized token after attach so the old binding epoch remains producible, and cursor-progress facts are keyed per participant rather than stored in the contract’s fixed occurrence array. The array cannot represent two participants advancing over the same retained suffix, so completion ordering is instead enforced by typed transitions and tests.

Structs§

ActiveBinding
Active binding authority.
ActiveIdentityRanks
Sorted unique permanent indexes of current live members.
AdmissionOrder
Stable admission ordering key for one lifecycle candidate.
AggregateOperationCommit
Aggregate durability barrier pairing one selected shell event with the consumed typed operation commit.
AggregateOperationFault
Fail-loud invariant report: a consumed typed commit disagreed with itself.
AggregateOperationRefusal
Refused aggregate decision retaining the unchanged shell and the intact consumed operation commit.
AllocatedParticipantSlot
Opaque, checked participant-slot allocation consumed by enrollment.
AttachCommit
Complete atomic result of a credential attach.
AttachCommitParameters
Result allocation owned by one successful credential-attach transaction.
AttachFrontierCharges
Exact charges for a credential attach’s one or two retained rows.
AttachedLifecycleRecord
Exact committed Attached lifecycle fact.
AttachedOperation
Durable facts of one committed credential attach, as recorded by the shell.
AttachedRecordPosition
Assigned ordering and delivery position of one Attached lifecycle record.
BindingFateOperation
Durable facts of one observed binding fate (crash/death), as recorded by the shell.
BindingOrigin
Opaque durable origin of one current or last authoritative binding.
BindingTerminalOwner
Exact active binding-terminal claim authority.
BoundParticipantCursor
One currently bound participant’s durable cumulative-cursor state.
CapacityCounter
Validated occupancy bounded by one nonzero signed limit.
ClaimFrontierError
Deterministic claim-frontier restoration failure.
ClaimFrontiers
Validated participant-keyed sequence and order claim authority.
ClaimFrontiersRestore
Public persisted input for restoring both coupled claim frontiers.
ClosureAccounting
Validated unchanged-prestate closure accounting.
ClosureDebt
Nonzero componentwise closure debt.
CommittedBindingTerminalPosition
A durable binding-terminal record was appended in the fate transaction.
CommittedBindingTerminalRestore
Raw durable fields for one committed binding terminal.
CommittedDetach
Committed detach replay cell with its real Detached record sequence.
CommittedDetachTransition
Atomic durable result of an immediately committed or drained detach.
CommittedDetachedTerminal
Appended Detached terminal with a cause valid for that record class.
CommittedDiedTerminal
Appended Died terminal with a cause valid for that record class.
CommittedOrdinaryRecord
Ordinary record selected for one successful atomic transaction.
ConnectionConversationCapacityCommit
Atomic successful result of semantic connection-capacity admission.
ConnectionIncarnationAllocation
Successful connection-incarnation allocation and resulting durable state.
ConnectionIncarnationAllocator
Validated monotonic connection-incarnation allocator state.
ConnectionIncarnationAllocatorRestore
Raw durable connection-incarnation allocator header.
ConnectionOrdinalExhaustionCommit
Atomic fixed-header update after a referenced terminal collision.
ConnectionOrdinalExhaustionReplay
Idempotent refusal from an already terminal connection-ordinal header.
ConversationCommit
Ownership barrier between event selection and durable append.
ConversationEvent
Opaque durable event emitted only by a protocol decision or canonical decode.
ConversationGenesis
Immutable genesis configuration for one participant conversation.
ConversationRefusal
Refused decision retaining the unchanged aggregate for continued use.
ConversationReplayFailure
Failed replay retaining the byte-for-byte unchanged pre-state.
CredentialAttachCapacityCommit
Atomic successful credential-attach capacity reservation.
CredentialAttachCapacityCounters
The five ordered receipt/provenance counters for credential attach.
CredentialAttachLiveReceipt
Stored canonical credential-attach result while its secret-bearing receipt remains live.
CredentialAttachProvenance
Non-secret credential-attach provenance retained after deleting the live verifier and secret body.
CursorEpisodeRestore
Complete raw state for one participant-scoped nonzero-debt cursor episode.
CursorProgressContinuous
Continuous cursor-progress witness with no delivered marker.
CursorProgressFacts
Variable participant-scoped cursor facts; no fixed occurrence array exists.
CursorProgressKey
Participant-scoped cursor progress key mandated by extraction Fix 2.
CursorProgressMarker
Marker-backed cursor-progress witness.
DebtCompletion
Validated completion restricted to clear, observer projection, or physical compaction.
DetachLookupContext
Complete serialized context for exhaustive detach reference lookup.
DetachedCredentialRecovery
Detached fenced credential-recovery witness.
DetachedCredentialRecoveryRestore
Marker-backed detached credential-recovery provenance.
DetachedCursorRelease
Leave-only detached-cursor release witness.
DetachedMarkerRelease
Leave-only undelivered-marker release witness.
DetachedMarkerReleaseRestore
Undelivered-marker release provenance.
DetachedOperation
Durable facts of one committed clean detach, as recorded by the shell.
DurableIncarnationReferences
Complete bounded live and durable connection-incarnation references.
EmptyDetach
Empty detach replay cell.
EnrolledOperation
Durable facts of one committed enrollment, as recorded by the shell.
EnrollmentCapacityCommit
Atomic successful enrollment capacity reservation.
EnrollmentCapacityCounters
All seven stage-8 counters for a fresh enrollment.
EnrollmentCommit
Complete atomic enrollment result.
EnrollmentCommitParameters
Values allocated by one successful enrollment transaction.
EnrollmentFingerprint
Consuming-layer enrollment-token fingerprint with no protocol-invented width.
EnrollmentLiveReceipt
Stored secret-bearing enrollment receipt while its receipt deadline is live.
EnrollmentProvenance
Non-secret enrollment provenance retained after the live receipt is deleted.
Event
Opaque typed completion event.
ExitProductRange
Validated compact L_other x E product range.
ExitProductRangeRestore
Persisted L_other x E product-range descriptor supplied during restoration.
FencedAttachCommit
Opaque proof that an exact marker-fenced attach committed.
FencedAttachCommitRestore
Complete predecessor and event fields for a committed fenced attach.
FreshParticipantCapacityCounter
Provably empty, nonzero per-participant capacity for fresh enrollment.
FrontierParticipant
Participant-indexed membership fact used by claim validation and planning.
HistoricalMarkerDeliveryFactRestore
Raw immutable fact that one retained marker was durably delivered to an exact historical binding epoch.
ImmutableOrderCandidateMajor
Validated immutable candidate-major group.
ImmutableOrderCandidateMajorRestore
Public persisted candidate-major group supplied during restoration.
InitialEnrollmentClosureInput
Durable state and signed configuration required by initial enrollment.
InitialEnrollmentClosureProjection
Fully derived, persistable initial-enrollment closure projection.
InitialEnrollmentCommitValues
Values minted or deadline-derived only after every admission gate passes.
InitialEnrollmentFrontierCommit
Atomic protocol-owned initial-enrollment frontier result.
InitialEnrollmentFrontierFailure
Failed initial-frontier derivation retaining the speculative operation.
InitialEnrollmentOperationCommit
Complete atomic initial-enrollment commit.
InitialEnrollmentOperationInput
Persisted prestate read by one initial EnrollmentRequest attempt.
KClaimBackedDetachedLeave
Validated evidence for an exact-current K-backed detached Leave.
LeaveCommit
One indivisible committed Leave state update.
LeaveCommitParameters
Allocation fields for settled bound or detached Leave.
LeaveCommittedRestore
Raw fields of the canonical permanent LeaveCommitted result.
LeaveFingerprint
Consuming-layer canonical Leave-request fingerprint.
LeftOperation
Durable facts of one permanent Leave, as recorded by the shell.
LiveFrontierCommit
A typed lifecycle commit paired with its complete post-transition owner.
LiveFrontierFailure
Failed live transition retaining the unchanged complete owner and operation.
LiveFrontierOwner
Complete executable frontier, closure-accounting, and keyed-retention owner.
LiveIdentityRestore
Raw durable fields for the latest committed terminal retained by membership.
LiveLeaveCommit
Complete move-only settled Leave result: tombstone and executable owner.
LiveMember
Live participant membership plus permanent enrollment and terminal history.
LiveMemberRestore
Complete persistence input for restoring one live member.
MarkerAckCommit
Atomic zero-debt marker-ack commit.
MarkerCandidateAuthority
Complete immutable marker candidate authority.
MarkerCursorProgressRestore
Marker-backed cursor provenance retaining its exact delivery predecessor.
MarkerDelivery
Exact marker-delivery witness.
MarkerDeliveryProjection
Move-only typed wire projection of one protocol-selected compaction marker.
MarkerDeliveryRestore
Raw predecessor fields proving exact marker delivery.
MarkerDrainCommit
Complete atomic marker-drain commit.
MarkerProofPermit
Opaque authority for an exact delivered marker and originating operation.
MarkerProofState
Durable participant facts read by the total marker-proof selector.
MovableOrderClaim
One exact movable transaction-order claim.
MovableSequenceClaim
One exact movable direct sequence claim.
NonzeroDebtAckOperation
Durable facts of one nonzero-debt participant cursor acknowledgement, as recorded by the shell.
NonzeroDebtCursorEpisode
Participant-scoped cursor accounting for one provably nonzero-debt episode.
NonzeroParticipantAckCommit
Atomic nonzero-debt participant-ack commit.
ObserverFloorPermit
Opaque proof that one protocol-computed candidate floor passed stage 11.
ObserverProgressAdvanceTransaction
Ownership barrier between a validated progress advance and its durable append.
ObserverProgressProjection
Move-only exact observer-progress projection emitted by a committed source.
ObserverProgressTrackTransaction
Ownership barrier between a validated registration and its durable append.
ObserverProjection
Observer-projection witness.
ObserverRecoveryAggregate
Exclusively owned observer-recovery aggregate: per-conversation hard observer progress plus every installed equal-epoch arm, as ONE owned unit.
ObserverRecoveryArm
One equal observer epoch that must be armed by an accepted recovery batch.
ObserverRecoveryCommit
Whole-batch observer-recovery commit selected after exhaustive validation.
ObserverRecoveryTransaction
Ownership barrier between arm selection and atomic arm installation.
OrderAllocation
Successful allocation of one unreserved transaction-order major.
OrderClaimFrontier
Validated exact transaction-order claim frontier.
OrderClaimFrontierRestore
Public persisted input for transaction-order-frontier restoration.
OrderClaims
Movable unmaterialized transaction-order claims.
OrderLedger
Validated transaction-order high watermark and reserved claims.
OrdinaryBindingAuthority
Opaque authority for the current epoch produced by an ordinary attach.
OrdinaryBindingAuthorityRestore
Raw predecessor fields for an ordinary-attach binding authority.
OrdinaryBindingFate
Exact no-marker fate derived from an ordinary attach and its durable death.
OrdinaryBindingFateRestore
Exact ordinary-binding fate provenance for cursor release.
OrdinaryDetachedAttachAdmission
Opaque proof that ordinary detached attach entered from a legal closure state.
OrdinaryProjectionLimits
Signed closure limits used by one ordinary fixed-point projection.
OrdinaryRecordDrainFirst
Sealed globally earlier candidate paired with its unchanged frontier state.
OrdinaryRecordProjectionFailure
Recoverable noncommit from the consuming ordinary projection.
OrdinaryRecordProjectionInput
External facts and signed limits for one consuming ordinary projection.
ParticipantAckCommit
Atomic zero-debt participant-ack commit.
ParticipantConversation
Event-sourced participant conversation.
ParticipantConversationRestore
Complete raw participant-conversation snapshot for public cold restore.
ParticipantConversationState
Fully validated whole-conversation participant state.
PendingBindingTerminalPosition
A binding fate was durably accepted but its terminal append remains pending.
PendingDetach
Pending detach replay cell whose terminal record is observer-blocked.
PendingDetachTransition
Atomic durable result of accepting an observer-blocked detach.
PendingDetachedFinalization
Pending Detached terminal with no possible Died-only cause.
PendingDiedFinalization
Pending Died terminal with no possible Detached-only cause.
PendingFinalizationRestore
Raw durable fields for one pending binding terminal.
PendingLeaveCommitParameters
Allocation and ordering proof for positional pending-terminal Leave.
PendingRecoveredCursorRelease
Latent cursor-release suffix while an earlier OP/PC witness remains stored.
PendingRecoveredCursorReleaseRestore
Durable latent cursor-release suffix while an OP/PC predecessor remains stored.
PendingReplayRequest
Verified command that forces pending replay through the progress/drain rule.
PhysicalCompaction
Physical-compaction range witness.
PlannedEnrollmentMarker
Planned marker owned by a newly overtaken enrollment participant.
PreparedLeaveAuthority
Linear order-lane authority for one exact settled or positional Leave.
ProjectedOrdinaryRecord
Sealed ordinary fixed-point poststate for one atomic durable transaction.
ProjectionCompactionSuccessor
Strict/later successor authority for OP, PC, and greater cumulative ack.
ReceiptDeadlines
Checked receipt and provenance deadlines derived from one admitted clock read.
RecipientAckObligations
Validated durable delivery obligations for one participant ack frontier.
RecordAdmissionCommit
Atomic ordinary-record commit selected by every shared admission gate.
RecordAdmissionDrainFirst
Earlier immutable candidate paired with the unchanged replayable aggregate.
RecordAdmissionFailure
Internal fault paired with the unchanged replayable aggregate.
RecordAdmissionPersistenceParts
Exact successful record-admission parts for one atomic persistence commit.
RecordAdmissionPrestate
Complete unchanged durable prestate consumed by ordinary admission.
RecordAdmissionRefusal
Exact wire response paired with the unchanged replayable aggregate.
RecordSizePermit
Successful static ordinary-record size preflight.
RecoveredBindingFate
Exact recovered-binding fate authority derived from a fenced attach.
RecoveredBindingFateRestore
Complete fenced-attach predecessor for a recovered binding-fate authority.
RecoveredCursorRelease
Exact released state when binding fate covers storage immediately.
RecoveryClaimProvenance
Sealed recovery-claim provenance derived from one exact stored edge.
RecoveryFencePermit
Successful stage-7 proof that no recovery fence applies.
RecoveryOrderActiveBindingRestore
Optional leading A member of a persisted DCR order interval.
RecoveryOrderBlock
Validated indivisible DCR order interval.
RecoveryOrderBlockRestore
Public persisted shape of the sole DCR order interval.
RecoverySequenceBlock
Validated indivisible DCR sequence interval.
RecoverySequenceBlockRestore
Public persisted shape of the sole DCR sequence interval.
RecoverySequenceTerminalRestore
Optional leading T member of a persisted DCR sequence interval.
RemainingClosurePermit
Successful remaining closure gate.
ReplacementTerminalProductRange
Validated compact L x RT product range.
ReplacementTerminalProductRangeRestore
Persisted L x RT product-range descriptor supplied during restoration.
RequiredCapacityPlan
Componentwise maximum required capacity across a finite successor plan.
ResultingEnrollmentCapacityCounters
All seven post-enrollment identity and receipt/provenance counters.
RetainedCausalRecord
One typed retained record fact used for candidate-key and provenance checks.
RetainedRecordCharge
Exact durable charge keyed to one validated retained causal row.
RetiredIdentity
Permanent retired identity tombstone.
RetiredIdentityRestore
Complete raw durable tombstone fields.
SequenceAdmission
Successful sequence-reserve admission.
SequenceClaimFrontier
Validated exact sequence claim frontier.
SequenceClaimFrontierRestore
Public persisted input for sequence-frontier restoration.
SequenceClaims
Primitive participant-lifecycle claims from which the sequence reserve is derived.
SequenceLedger
Validated delivery-sequence watermark and all unmaterialized claims.
SequenceProductRanges
Validated O(I) product descriptors for the sequence frontier.
SequenceProductRangesRestore
Compact persisted product descriptors supplied during restoration.
ServerIncarnationExhaustion
State-preserving terminal server-incarnation refusal.
ServerIncarnationFsyncIntent
Checked startup write which must be fsynced before participant mode starts.
TerminalProductRange
Validated compact L x T product range.
TerminalProductRangeRestore
Persisted L x T product-range descriptor supplied during restoration.
TerminalizedDetach
Terminalized detach replay cell retained after a successful attach.
UnchangedRecordAdmission
Complete unchanged operation state returned by every noncommit decision.
VerifiedAttachCommit
Successful attach proof; fields are private so only mode verification mints it.
VerifiedCommittedDetach
Exact verified view of a committed detach cell.
VerifiedDetachRequest
Detach request proven to match one active binding.
VerifiedLeaveRequest
Exact Leave request authority proven against one live member.
VerifiedPendingDetach
Exact verified view of a pending detach cell.
VerifiedTerminalizedDetach
Exact verified view whose receiver is the sole state-derived constructor for TerminalizedDetachCell.

Enums§

AggregateOperationDecision
Total aggregate decision for one lifecycle operation.
AggregateOperationFaultReason
Reason a consumed typed commit could not repeat itself as an event body.
AttachCommitError
Failure while atomically applying a previously verified attach.
AttachSecretProof
Secret-verifier result supplied by the consuming cryptographic layer for credential attach lookup.
AttachTransition
Binding-terminal effect selected by one successful attach.
AttachVerificationError
Failure while proving credential-attach authority before commit.
BindingFateTerminalRestore
Durable binding-fate terminal provenance, whether appended or still pending.
BindingRequiredLookupResult
Total shared lookup result for ack, marker-ack, and ordinary admission.
BindingSlotDecision
Stage-6 participant binding-slot result, bound to the requesting operation’s response authority.
BindingSlotOccupancy
Current participant occupancy of one connection/conversation binding slot.
BindingState
Binding-slot state; pending finalization carries no live authority.
BindingStateRestore
Durable binding-slot representation with raw pending-terminal fields.
BindingTerminalDisposition
Durable placement selected by an unrefusable binding-fate transaction.
BindingTerminalKind
Binding-terminal lifecycle record kind, derived from cause-partitioned state.
CapacityCounterInvariantError
Invalid persisted occupancy for one signed nonzero capacity.
ClaimFrontierCounter
Counter whose frontier failed restoration.
ClaimFrontierInvalidReason
Structural reason for a claim-frontier failure.
ClosureAccountingError
Invalid durable closure-accounting state.
ClosureState
Closure state makes a clear edge with nonzero debt unconstructible.
ClosureStateRestore
Raw closure state; a stored edge always carries a raw nonzero debt vector.
CommittedBindingTerminal
Cause-partitioned durable binding-terminal record.
ConnectionConversationTracking
Whether a semantic request’s conversation already owns a connection slot.
ConnectionIncarnationAllocationDecision
Connection-ordinal allocation decision.
ConnectionIncarnationAllocatorRestoreError
Invalid durable connection-incarnation allocator header.
ConnectionOrdinalExhaustion
Exact ordinal-exhaustion transition.
ConversationDecision
Protocol decision that either owns one pending durable commit or refuses it.
ConversationEventDecodeError
Stable canonical event-decode failure.
ConversationOperation
One of the six lifecycle operations recordable by the conversation shell.
ConversationRefusalReason
Reason a protocol decision emitted no durable event.
ConversationReplayError
Semantic durable-replay failure for a structurally decoded event.
ConversationStateRestoreError
Failure while jointly restoring claim frontiers and their current closure edge.
CredentialAttachCapacityDecision
Exhaustive stage-8 credential-attach runtime-capacity result.
CredentialAttachLookupResult
Total credential-attach lookup result through authority phase 3.
CredentialAttachTokenPhase
Phase selected by credential-attach token lookup.
CumulativeAckAuthorizationError
Authority failure before a cumulative-ack transition.
CumulativeAckOutcome
Exhaustive outcome of an authority-checked normal cumulative ack.
CursorEpisodeBuildError
Construction failure for a participant-scoped nonzero-debt episode.
CursorFactEncodeError
Deterministic cursor-fact serialization failure.
CursorFateSuccessor
Closed cursor-fate result taxonomy retained for API compatibility.
CursorProgressFact
Durable cursor-progress fact state.
DebtCompletionRestore
Raw durable successor class accepted by detached Leave or fenced attach.
DetachCell
Exact four-variant detach cell mandated by the extraction brief.
DetachCellRestore
Exact four-state durable detach replay cell.
DetachCommitError
Invalid previous-cell state for accepting a new detach.
DetachLookupResult
Total result of detach participant/token/binding lookup.
DetachReplayError
Exact-token replay verification failure.
DetachTokenResolution
Exact-token resolution state for the identity-slot detach cell.
DetachVerificationError
Authority mismatch between an active binding and detach request.
DetachedAttachRefusal
Exact refusal selected by a detached edge or charged retarget check.
DetachedBindingTransition
Result of a fate that records a Detached lifecycle terminal.
DetachedCursorReleaseProvenanceRestore
Provenance alternatives capable of constructing DetachedCursorRelease.
DiedBindingTransition
Result of a fate that records a Died lifecycle terminal.
DurableIncarnationReferencesError
Error constructing a bounded complete durable-reference collection.
EnrollmentCapacityDecision
Exhaustive stage-8 enrollment runtime-capacity result.
EnrollmentCommitError
Failure while committing a previously allocated enrollment.
EnrollmentLookupResult
Total enrollment-token lookup result through phase 0c.
EnrollmentTokenPhase
Phase-specific enrollment-token lookup state after the lifetime token index has run.
FreshParticipantCapacityCounterInvariantError
Invalid restored occupancy for a participant that has not yet been minted.
FrontierBinding
Exact live participant binding state used by marker planning.
HistoricalCausalFactRestore
Raw durable facts for one compacted causal lifecycle record.
IdentityState
Present participant identity state; absence is represented outside this enum.
ImmutableSequenceCandidate
Immutable assigned candidate above the current sequence high watermark.
InitialEnrollmentClosureError
Malformed durable/configuration input for initial enrollment projection.
InitialEnrollmentFrontierError
An admitted initial enrollment disagreed with its typed frontier projection.
InitialEnrollmentOperationDecision
Exhaustive initial-enrollment operation result.
InitialEnrollmentOperationFault
Internal invariant fault separated from every wire-visible outcome.
LeaveCommitError
Failure while applying an already-authorized Leave transaction.
LeaveLookupResult
Total result of Leave participant/token/binding lookup.
LeaveSecretProof
Result of the permanent Leave-token verifier supplied by the consuming cryptographic layer.
LeaveVerificationError
Failure while proving a live member’s exact Leave request authority.
LiveFrontierError
Failure selected while coupling a sealed lifecycle commit to live ownership.
LiveLeaveError
Typed failure of the protocol-owned settled Leave live transition.
MarkerAckCommitError
Failure while applying an already-selected marker-ack commit.
MarkerAckDecision
Total zero-debt marker-ack decision.
MarkerDrainError
Exact invariant fault selected by mandatory marker drain.
MarkerProofDecision
Exhaustive result of marker-proof selection after common authority.
MarkerProofInput
Operation-specific marker-proof input after common authority validation.
MarkerProvenance
Immutable origin of one planned or appended marker value.
MarkerSequenceOwner
Current logical owner of one marker-provenance value.
MembershipInvariantError
Invalid durable membership/history combination.
NonzeroAckEpisodePosition
Durable episode position supplied while applying an aggregate ack commit.
NonzeroParticipantAckCommitError
Failure while applying an already-selected nonzero-debt ack commit.
NonzeroParticipantAckDecision
Total nonzero-debt participant-ack decision.
NonzeroParticipantAckInvariantError
Durable aggregate mismatch found after common request authority succeeded.
ObserverCheckedOperation
Operations whose candidate floor is checked against hard observer retention.
ObserverFloorDecision
Stage-11 observer hard-retention decision.
ObserverProgressAdvanceDecision
Total transactional progress-advance decision against the owned aggregate.
ObserverProgressAdvanceError
Failure while advancing hard observer progress.
ObserverProgressTrackDecision
Total transactional registration decision against the owned aggregate.
ObserverProgressTrackError
Failure while registering a newly tracked conversation.
ObserverRecoveryAggregateRestoreError
Restore-time validation failure for the owned observer-recovery aggregate.
ObserverRecoveryDecision
Total observer-recovery decision.
ObserverRecoveryTransactionDecision
Total transactional observer-recovery decision against the owned aggregate.
OrderAdmissionError
Order admission refusal or impossible simulated state.
OrderClaimsInvariantError
Invalid primitive order-claim state.
OrderDirectOwner
Direct movable transaction-order owner stored in a bounded identity slot.
OrderHigh
Persisted transaction-order high-watermark state.
OrderLedgerInvariantError
Invalid persisted order ledger.
OrdinaryProjectionError
Invalid or noncommitting ordinary fixed-point snapshot.
OrdinaryRecordProjectionDecision
Consuming fixed-point result for one optional ordinary record.
ParticipantAckCommitError
Failure while applying an already-selected participant-ack commit.
ParticipantAckDecision
Total zero-debt participant-ack decision.
ParticipantBindingRequest
Binding-required participant request families that share lookup phases 1 through 5.
ParticipantCursorProgress
Cursor progress split into typestates rather than an optional marker bag.
ParticipantLifecycleRestore
Complete event-replayed participant state, with tombstone precedence in the type.
ParticipantSlotAllocationError
Invalid participant-slot allocation proof.
PendingDrainDecision
Result of the mandatory ordered drain attempt on advanced observer progress.
PendingFinalization
Binding authority ended, but its terminal record awaits durable append.
PendingReplay
Atomic durable result of exact-token pending replay.
PendingReplayError
Invalid pending replay input or paired state.
PrepareLeaveAuthorityError
Failure to consume the exact order authority for a Leave transaction.
PresentedIdentity
Result of resolving the presented participant key before operation-specific authority checks.
ReceiptDeadlineError
Failure to derive the frozen receipt/provenance deadline pair.
RecipientAckObligationsContextError
The testimony belongs to another participant or durable ack prestate.
RecipientAckObligationsError
Malformed durable recipient-obligation testimony.
RecordAdmissionDecision
Exhaustive ordinary-record operation result.
RecordAdmissionFault
Internal durable/configuration fault, distinct from every wire outcome.
RecordSizeDecision
Static ordinary-record size decision in entry-before-byte order.
RecoveredBindingFateTransition
Preserve-or-cover result for cursor-releasing binding fate against OP/PC.
RecoveredStorageCompletionRestore
Exact completion event consuming a latent OP/PC predecessor.
RecoveryFenceDecision
Stage-7 recovery-fence decision.
RecoveryQuartetStatus
Whether one enrollment projection endows the sole recovery quartet.
RecoverySequenceReserve
Edge-owned recovery sequence claims.
RemainingClosureDecision
Stage-12 closure decision after observer admission.
RequiredCapacityPlanError
Invalid required-capacity simulation.
ResolvedIdentity
Identity reached through an exact token index before the presented-key identity lookup runs.
RestoredBindingFateTerminal
Validated binding-fate terminal provenance.
RestoredParticipantLifecycle
Validated runtime participant state restored from durable data.
RetainedCausalRecordKind
Exact typed body class for one retained causal record.
RetirementError
Mismatch between a live member and proposed stored Leave result.
SemanticConnectionCapacityDecision
Stage-6 semantic connection-capacity result.
SequenceAdmissionError
Sequence admission refusal.
SequenceDirectOwner
Direct sequence-claim owner stored in an identity slot.
SequenceLedgerInvariantError
Invalid persisted sequence ledger.
SequenceProductClass
Product class that may own a value before its causal transaction fires.
ServerIncarnationStartupDecision
Startup decision for the checked server-incarnation increment.
StorageRestoreError
A durable lifecycle capsule failed a protocol invariant.
StoredEdge
Exact seven non-clear stored edge kinds.
StoredEdgeRestore
Exact seven-kind stored-edge representation with provenance where required.
TerminalProductSource
Terminal source retained by immutable marker provenance.

Traits§

LeaveOnlyEdge
Sealed intended-dead-end contract for DMR and DCursor.
ParticipantSlotAllocatorProof
Consuming allocator proof for one permanent participant reservation slot.

Functions§

allocate_connection_incarnation
Allocates one checked connection ordinal, skipping every exact collision.
apply_attach_frontier
Applies credential attach to the complete live owner.
apply_detach_frontier
Applies a committed detach terminal to the complete live owner.
apply_enrollment_frontier
Applies a subsequent enrollment to the complete live owner.
apply_initial_enrollment
Applies frozen stages 2, 6, and 8-13 to initial enrollment.
apply_marker_ack
Applies the complete zero-debt marker-ack selector.
apply_marker_ack_frontier
Applies a zero-debt marker acknowledgement cursor transition.
apply_nonzero_participant_ack
Applies the complete nonzero-debt normal-ack selector.
apply_nonzero_participant_ack_frontier
Applies a nonzero-debt participant acknowledgement cursor transition.
apply_nonzero_participant_ack_with_obligations
Applies the nonzero-debt selector with durable recipient obligations.
apply_participant_ack
Applies the complete zero-debt participant-ack selector.
apply_participant_ack_frontier
Applies a zero-debt participant acknowledgement cursor transition.
apply_participant_ack_with_obligations
Applies the Unit 2 durable-obligation endpoint rule after shared lookup.
apply_record_admission
Applies frozen stages 4-12 and constructs the exact phase-13 record commit.
check_observer_floor
Applies the observer hard-retention selector to a protocol-computed floor.
check_record_size
Applies the frozen stage-8 RecordTooLarge selector.
check_recovery_fence
Applies the stage-7 recovery-fence predicate before numeric admission.
check_remaining_closure
Applies the remaining closure order: delivered marker, churn, then capacity.
classify_record_admission_binding
Classifies one ordinary record admission through the shared binding-required lookup WITHOUT consuming any claim-frontier authority.
commit_attach
Atomically commits a verified attach and applies Fix 1’s detach-cell rule.
commit_detach
Commits an immediate detach atomically with binding release.
commit_enrollment
Atomically creates membership, binding, Attached, and canonical receipt.
commit_leave
Commits bound or already-detached Leave, deriving all optional result fields.
commit_pending_leave
Positionally commits one pending binding terminal immediately before Left.
commit_pending_leave_frontier
Commits a pending binding terminal immediately before Leave through one complete live owner.
commit_settled_leave_frontier
Commits settled bound or detached Leave through one complete live owner.
complete_pending_detach
Completes one paired pending finalization and detach replay cell.
decide_attached_operation
Selects the aggregate Attached event for one consumed attach commit.
decide_detached_operation
Selects the aggregate Detached event for one consumed detach transition.
decide_enrolled_operation
Selects the aggregate Enrolled event for one consumed enrollment commit.
decide_left_operation
Selects the aggregate Left event for one consumed leave commit.
decide_nonzero_debt_ack_operation
Selects the aggregate NonzeroDebtAck event for one consumed ack commit.
decide_ordinary_binding_fate_operation
Selects the aggregate BindingFate event for one consumed ordinary fate.
decide_recovered_binding_fate_operation
Selects the aggregate BindingFate event for one consumed recovered fate.
drain_next_marker
Consumes the globally first marker candidate into one atomic durable commit.
lookup_binding_required
Applies the common tombstone, unknown, generation, and exact-binding order for participant ack, marker ack, and ordinary admission.
lookup_credential_attach
Applies credential-attach token lookup, tombstone precedence, verifier order, and ordinary live-authority checks.
lookup_detach
Applies the total participant lookup and detach-cell precedence.
lookup_enrollment
Applies token-to-identity tombstone precedence and enrollment’s three live token phases.
lookup_leave
Applies the committed-Leave exception, tombstone precedence, and live Leave authority/binding order.
prepare_server_incarnation_startup
Produces the checked startup fsync intent or exact server exhaustion.
project_initial_enrollment_closure
Projects the complete initial-enrollment closure transition.
select_credential_attach_binding_slot
Selects credential-attach binding occupancy, permitting only an empty slot or rotation of the same presented participant.
select_credential_attach_capacity
Applies credential attach’s exact five-scope runtime-capacity order.
select_enrollment_binding_slot
Selects enrollment binding-slot occupancy without revealing its occupant.
select_enrollment_capacity
Applies the fixed enrollment runtime-capacity order atomically.
select_marker_proof
Applies the frozen total marker-proof selector in its exact precedence order.
select_semantic_connection_capacity
Applies semantic connection-conversation capacity before participant mutation.
start_blocked_detach
Starts an observer-blocked detach with terminal authority already ended.

Type Aliases§

AggregateOperationResult
Total aggregate decision, or the fail-loud pairing fault for the two producers whose event bodies revalidate their consumed commit.
LiveFrontierResult
Result of coupling any typed lifecycle commit to live frontier ownership.